Iranian Foreign Ministry: "Continuing Message Exchanges with the U.S. and Activities of Mediating Countries"
Esmaeil Baghaei, Spokesperson for the Iranian Ministry of Foreign Affairs [Xinhua, Yonhap News file photo]Esmaeil Baghaei, spokesperson for the Iranian Ministry of Foreign Affairs, stated on the 26th
President Yoon: "Do You Think You Are Safe from the Special Counsel?"... Final Statement Video Released
President Yoon Suk Yeol rebuking the special prosecutor on the 24th. [Court video / @birds_justice X account subtitle GIF] A video of President Yoon Suk Yeol's closing statement at his trial rega
President Yoon, regarding the first-instance ruling on the Public Official Election Act: “An excessive political verdict that distorts the facts… We will appeal immediately.”
The first-instance sentencing hearing for President Yoon Suk Yeol regarding violations of the Public Official Election Act is being broadcast live at Seoul Station on the 27th. [Photo=Yonhap News]Pres
WSJ: "SK Hynix ADR Premium Is a Sign of AI Trading Overheat"
Advertisement for SK Hynix ADR listing in New York's Times Square [Reuters=Yonhap News file photo]The Wall Street Journal (WSJ) has pointed out that the price of SK Hynix’s American Depositary Recei
'Godfather of Japanese Mystery Novels' Keigo Higashino Passes Away After Battle with Cancer at 68
Famous Japanese mystery novelist Keigo Higashino [AFP=Yonhap News]It has been belatedly reported that Keigo Higashino, the "godfather of Japanese mystery novels" and author of bestsellers such as "The
[Park Pil-kyu Security Column] To the Ignorant Trying to Clothe a Beast in Sheep's Clothing
Rep. Kim Byung-joo of the Democratic Party of Korea [Photo=Yonhap News]“The Air Force Academy doesn't teach you how to fly a plane!” “The Army, Navy, and Air Force academies are exactly the
North Korean hacking [Yonhap News]
A malicious hacking group, believed to be supported by the North Korean government, has been found stealing information by mimicking popular code packages frequently used by software (SW) developers worldwide.
JFrog Security Research, a global software company based in Silicon Valley, announced on the 4th (local time) that it had discovered six malicious packages on 'npm,' the official software repository for JavaScript developers, that were sophisticated imitations of well-known code bundles.
When coding, developers generally do not write every single part of a program from scratch; instead, they frequently download commonly used functions from public repositories as needed.
It is much like a carpenter buying standardized nails from a hardware store when building furniture.
Exploiting this practice, hackers mimicked popular code packages—some downloaded over 1.2 million times a month—inserted malicious code, and uploaded them under names very similar to the originals.
For example, they used names like 'rollup-packages-polyfill-core' or 'rollup-runtime-polyfill-core,' which could easily be confused with the legitimate code package 'rollup-plugin-polyfill-node.'
They exploited the fact that developers often search for packages using only partial names, such as "rollup polyfill," rather than typing the full package name.
The manuals and website addresses included were also identical to the originals, making them indistinguishable unless examined very closely.
They also incorporated several elaborate evasion techniques to avoid detection by malware scanners.
For one, the code was designed to remain dormant if it detected it was running in a 'sandbox' environment used for threat detection.
Furthermore, they employed multi-stage methods: hiding malicious functions within normal-looking code or omitting the core malicious payload entirely from the package, instead having it secretly downloaded and executed from an external source during installation or runtime.
As a result, it is difficult to identify the malware by simply scanning the package itself.
This attack is a "software supply chain attack" tactic that targets the entire corporation by using the computers of developers building corporate systems as a stepping stone, rather than targeting ordinary internet users.
It is estimated that the hackers intended to monitor computer screens, seize control of computers, and steal cryptocurrency wallets and login credentials.
JFrog Security Research explained that the multi-stage structure, camouflage techniques, and methods of information theft and remote control used in this attack match the operational patterns of 'Lazarus,' a group identified by the U.S. government as being linked to North Korean hacking activities.
Lazarus is one of the three major hacking organizations known to be under North Korea's Reconnaissance General Bureau, alongside Kimsuky and Andariel, and was identified as the group responsible for hacking the South Korean cryptocurrency exchange Upbit last year.
Some of the fake packages uploaded to the repository have been suspended following emergency sanctions. However, the research institute urged developers and companies that may have already installed them to thoroughly check for potential damage.
Yonhap News More by this author